{
  "data": {
    "a": {
      "slug": "monday",
      "name": "monday.com",
      "vendor": "monday.com Ltd.",
      "vendorUrl": "https://monday.com",
      "kind": "http-api",
      "category": "project-management",
      "summary": "monday.com is a hosted work management platform built on boards, items and columns. Agents reach it through a GraphQL API at api.monday.com/v2 and an official hosted MCP server, using personal API tokens or OAuth.",
      "url": "https://www.anchorterminal.com/tools/monday",
      "markdownUrl": "https://www.anchorterminal.com/tools/monday.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/monday.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/monday.json",
      "repo": "https://github.com/mondaycom/mcp",
      "license": "Proprietary service under monday.com's Terms of Service and Developer Terms. The MCP server, agent toolkit and API SDK on GitHub are MIT",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.monday.com/v2",
      "packages": [
        {
          "registry": "npm",
          "name": "@mondaydotcomorg/api"
        },
        {
          "registry": "npm",
          "name": "@mondaydotcomorg/monday-api-mcp"
        },
        {
          "registry": "npm",
          "name": "@mondaydotcomorg/agent-toolkit"
        }
      ],
      "auth": "mixed",
      "authNotes": "Self-serve. A signed-in admin or member copies a personal API token from the developer centre and sends it in the `Authorization` header. The token has no scopes and mirrors the user's permissions, and each user has one, which can be regenerated. OAuth apps choose from 21 scopes such as `boards:read` and `updates:write`. The legacy OAuth flow issues tokens that don't expire, and the newer OAuth 2.1 flow adds PKCE, expiring access tokens, refresh tokens and revocation. The hosted MCP server takes OAuth with dynamic client registration or a personal token as a Bearer header. A publicly distributed MCP client must register through a review form first. A documented agent signup API returns an account and token with no browser step.",
      "pricing": "freemium",
      "pricingNotes": "Free plan with up to 2 seats and 3 boards, no card needed per the pricing page, plus a free developer sandbox account with up to 10 seats and 1,000 items per product, so an agent can start without a contract. Paid plans are per seat. The pricing page served our reader in pounds, at £8 (Basic), £11 (Standard) and £17 (Pro) a seat a month billed annually for 10 seats, with Enterprise through sales. The API has no per-call price. Daily calls are capped by plan (1,000, 10,000 on Pro, 25,000 on Enterprise) and the page says more can be bought, with no price shown (checked 2026-10-08).",
      "priceSummary": "Freemium",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the MCP docs, the agent skill files or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": 64,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 176164,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://developer.monday.com/api-reference/docs/basics",
      "llmsTxt": "https://developer.monday.com/api-reference/llms.txt",
      "registryName": "com.monday/monday.com",
      "capabilities": [
        "tasks.create",
        "tasks.update",
        "projects.manage",
        "tasks.comments",
        "projects.reporting",
        "work.docs",
        "forms.create"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "graphql",
        "closed-source",
        "free-tier",
        "oauth",
        "llms-txt",
        "webhooks",
        "idempotency",
        "javascript",
        "typescript",
        "status-page",
        "soc2",
        "agent-signup"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 76.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 33,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 82,
          "maintenance": 85,
          "payments": 50,
          "reliability": 79,
          "schema": 88,
          "security": 70,
          "transparency": 80
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "The GraphQL API publishes its full schema, accepts an `Idempotency-Key` header on mutations and reports limits in `RateLimit` headers, and a documented signup API lets an agent create its own account and token. Personal tokens carry every permission their user has, daily calls stop at 1,000 below Pro, and the status page shows two long platform incidents since July 2026.",
        "bestFor": "Teams that already run projects on monday.com boards and want an agent to create items, change status, post updates and read board summaries through MCP or GraphQL.",
        "strengths": [
          "Full GraphQL schema is public as SDL and JSON at api.monday.com/v2/get_schema, with a copy for each dated API version",
          "Mutations accept an `Idempotency-Key` header, with responses cached for 30 minutes and replays marked `Idempotency-Replayed: true`",
          "A documented signup API at signup-logic.monday.com creates an account and returns an API token after an agent captcha, with no browser step",
          "Hosted MCP server at https://mcp.monday.com/mcp with OAuth, PKCE and dynamic client registration, and 64 tools in the published reference",
          "Quarterly dated API versions, each stable for at least six months, with deprecations announced at least six months ahead"
        ],
        "weaknesses": [
          "Personal API tokens have no scopes. Each carries every permission its user has in the app",
          "1,000 API calls a day on Free, Basic and Standard, shared with MCP tool calls, against 10,000 on Pro and 25,000 on Enterprise",
          "status.monday.com lists a critical platform incident of 2 hours 8 minutes on 5 September 2026 and a major latency incident of 2 hours 57 minutes on 13 July 2026",
          "The MCP security page says self-service export of detailed MCP or API audit logs isn't available, and the audit log API is limited to Enterprise admins",
          "Column values travel as a JSON string whose shape depends on the column type, and the only official API SDK is for JavaScript and TypeScript"
        ],
        "agentNotes": [
          "Send an `API-Version` header such as 2026-10 on every call. Without it the API uses whichever version is current",
          "Read the board's columns first (`get_board_info` or `boards { columns }`), then write column values as a JSON string keyed by column ID",
          "Reuse one `Idempotency-Key` per mutation when retrying after a timeout or 5xx. After a 429, wait for `Retry-After` or `retry_in_seconds`",
          "Page items with `items_page` and `next_items_page`, at most 500 a page. Cursors expire after 60 minutes",
          "For a narrower grant than a personal token, connect MCP through a custom OAuth app with only scopes such as `boards:read`"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 76.4
          }
        ],
        "editorialScores": {
          "ergonomics": 82,
          "maintenance": 85,
          "payments": 50,
          "reliability": 79,
          "schema": 88,
          "security": 70,
          "transparency": 73
        },
        "provenanceScore": 86
      },
      "connect": {
        "install": "npx @mondaydotcomorg/monday-api-mcp@latest",
        "http": "curl -X POST https://api.monday.com/v2 \\\n  -H \"Authorization: YOUR_API_TOKEN\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"query\": \"query { me { id name } }\"}'",
        "config": {
          "mcpServers": {
            "monday-mcp": {
              "url": "https://mcp.monday.com/mcp"
            }
          }
        },
        "headless": {
          "mcpServers": {
            "monday-mcp": {
              "headers": {
                "Authorization": "Bearer YOUR_API_TOKEN"
              },
              "url": "https://mcp.monday.com/mcp"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/tasks.create",
        "tool": "https://letme.dev/monday"
      },
      "area": "business",
      "provenance": {
        "legalEntity": "monday.com Ltd.",
        "domain": "monday.com",
        "domainRegistered": "1995-07-19",
        "endpointOnVendorDomain": true,
        "terms": "https://monday.com/l/legal/tos/",
        "privacy": "https://monday.com/l/privacy/privacy-policy/",
        "statusPage": "https://status.monday.com",
        "changelog": "https://developer.monday.com/api-reference/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Terms of Service (last updated 5 May 2026) are between the customer and monday.com Ltd., 6 Yitzhak Sadeh St., Tel-Aviv 6777506, Israel. The privacy policy was last updated on 1 October 2026.",
          "The API answers at api.monday.com, the MCP server at mcp.monday.com and its authorisation server at auth.monday.com, all monday.com subdomains.",
          "monday.com/.well-known/security.txt, www.monday.com/.well-known/security.txt and monday.com/security.txt each return 404. The trust centre sends vulnerability reports to a form at monday.com/security/form.",
          "RDAP for monday.com gives a registration date of 1995-07-19.",
          "The Service Level Agreement for the Enterprise plan (last updated 20 December 2023) commits to 99.9 per cent monthly uptime for the core services. The DPA carries the same date."
        ],
        "score": 86
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/monday.json",
      "live": {
        "slug": "monday",
        "probe": {
          "target": "https://api.monday.com/v2",
          "method": "get",
          "lastAt": "2026-10-09T10:42:49.991285795Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 132,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 130,
          "p95ms24h": 194,
          "samples24h": 207,
          "samples30d": 207,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 93,
              "ok": 93
            },
            {
              "date": "2026-10-09",
              "probes": 114,
              "ok": 114
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.monday.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T10:41:49.042917793Z"
        },
        "versions": [
          {
            "registry": "mcp-registry",
            "name": "com.monday/monday.com",
            "version": "0.0.1",
            "seenAt": "2026-10-09T02:57:46.004536428Z"
          },
          {
            "registry": "npm",
            "name": "@mondaydotcomorg/agent-toolkit",
            "version": "5.73.0",
            "seenAt": "2026-10-08T16:21:49.787128646Z"
          },
          {
            "registry": "npm",
            "name": "@mondaydotcomorg/api",
            "version": "14.1.0",
            "seenAt": "2026-10-08T16:21:47.55416646Z"
          },
          {
            "registry": "npm",
            "name": "@mondaydotcomorg/monday-api-mcp",
            "version": "3.3.1",
            "seenAt": "2026-10-08T16:21:48.399378593Z"
          }
        ],
        "githubStars": 427,
        "npmWeekly": 176164,
        "securityTxt": {
          "url": "https://monday.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:08.858683148Z"
        },
        "pages": [
          {
            "url": "https://developer.monday.com/api-reference/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:15.57094829Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "392d3fee6fc8"
          },
          {
            "url": "https://monday.com/l/privacy/privacy-policy/",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:11.913568217Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "6d277c3c4400"
          },
          {
            "url": "https://monday.com/l/legal/tos/",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:09.717483007Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f28d7d1863fc"
          }
        ],
        "updatedAt": "2026-10-09T10:42:49.991285795Z"
      }
    },
    "answer": "monday.com scores 76.4 (BB) on agent readiness against OpenProject's 57.4 (C), and leads in 6 of 7 scored categories. OpenProject leads on transparency \u0026 trust.",
    "b": {
      "slug": "openproject",
      "name": "OpenProject",
      "vendor": "OpenProject GmbH",
      "vendorUrl": "https://www.openproject.org",
      "kind": "http-api",
      "category": "project-management",
      "summary": "OpenProject is open-source project management software for work packages, Gantt plans, boards and time tracking, sold as a cloud service and for self-hosting. Agents reach it through the APIv3 REST API, and paid plans add an MCP server.",
      "url": "https://www.anchorterminal.com/tools/openproject",
      "markdownUrl": "https://www.anchorterminal.com/tools/openproject.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/openproject.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/openproject.json",
      "repo": "https://github.com/opf/openproject",
      "license": "GPL-3.0 for the OpenProject source. Enterprise add-ons need a paid token, and OpenProject Enterprise cloud runs under OpenProject's Terms of Service",
      "transports": [
        "http"
      ],
      "packages": [],
      "auth": "mixed",
      "authNotes": "Access is self-serve. A user creates a named personal API token in account settings and sends it as `Authorization: Bearer`, or as the Basic auth password with the user name `apikey`. The token carries that user's permissions, and no per-token scope or expiry was found. An administrator can register OAuth 2.0 applications for the authorisation code grant, PKCE or client credentials, with one scope per API (`api_v3`, `mcp`, `scim_v2`, `bcf_v2_1`). JWTs from a configured OIDC provider are also accepted. No app review or partner approval is described.",
      "pricing": "freemium",
      "pricingNotes": "The Community edition is free to self-host with the REST API included, and the cloud has a 14-day trial with no credit card, so an agent can start without a contract. Cloud plans are per user per month on a yearly term, Basic $7.25 (from 5 users, $8.50 on a monthly term), Professional $13.50 (from 25 users) and Premium $19.50 (from 100 users), with Corporate on request. Euro prices are 5.95, 10.95 and 15.95. API calls are not priced. The MCP server needs Professional or above. Community is not sold as a cloud plan (https://www.openproject.org/pricing/, checked 2026-10-08).",
      "priceSummary": "$7.25 / seat-mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the API docs, the OpenAPI document or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 16352,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://www.openproject.org/docs/api/",
      "openapi": "https://www.openproject.org/docs/api/v3/spec.yml",
      "capabilities": [
        "tasks.create",
        "tasks.update",
        "projects.manage",
        "tasks.comments",
        "projects.reporting",
        "events.webhooks-send"
      ],
      "tags": [
        "official",
        "hosted",
        "self-hosted",
        "open-source",
        "rest",
        "openapi",
        "oauth",
        "mcp",
        "freemium",
        "free-trial",
        "webhooks",
        "status-page",
        "sla",
        "eu-hosting",
        "project-management"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.4,
        "grade": "C",
        "agentReady": false,
        "rank": 550,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 11,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 75,
          "payments": 30,
          "reliability": 52,
          "schema": 76,
          "security": 59,
          "transparency": 87
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -5,
        "negativeNotes": [
          "2026-06-08. 13 advisories rated critical were published against opf/openproject between January and June 2026, among them cache store poisoning leading to remote code execution (GHSA-qj96-f42f-6336, fixed in 17.3.3 and 17.4.1), SQL injection in the timestamps function (GHSA-98vw-2r87-fx2r) and a pre-authentication remote code execution in the Docker image through a default secret key (GHSA-r85r-gjq2-f83r, 13 May 2026). OpenProject published them itself, and its policy is to publish each advisory with the fixing release, so the deduction is reduced, -3 (https://github.com/opf/openproject/security/advisories).",
          "2026-09-30. 83 advisories in all were published in the twelve months to 8 October 2026, several of them missing permission checks in APIv3 that exposed private work package data across projects. Several credit the YesWeHack bounty sponsored by the European Commission. The advisories give self-hosted version numbers and do not say when the cloud was patched. Fixed and published, -2 (https://github.com/opf/openproject/security/advisories)."
        ],
        "verdict": "OpenProject's APIv3 has a public OpenAPI 3.1 document with 320 operations, stable error identifiers and optimistic locking, and the same API ships in the free GPL-3.0 Community edition. No request limits are published, API tokens carry their user's full permissions, and 83 security advisories were published in the last twelve months, 13 rated critical.",
        "bestFor": "Teams that want a self-hostable or EU-hosted project tool with Gantt, time tracking and budgets, and an agent working through a documented REST API.",
        "strengths": [
          "OpenAPI 3.1 document with 234 paths and 320 operations, public on the docs site and served by every instance at `/api/v3/spec.json`",
          "Errors carry a stable `errorIdentifier` URN, and validation failures list one entry per property",
          "The Community edition is GPL-3.0 and free to self-host with the REST API included, and the cloud trial needs no credit card",
          "Seven releases between 5 August and 1 October 2026, with security fixes published as GitHub advisories and CVEs",
          "The service description commits to 99.9 per cent yearly availability with service credits, and an EU shard keeps all sub-processors in the EU"
        ],
        "weaknesses": [
          "83 advisories published against opf/openproject in the twelve months to 8 October 2026, 13 rated critical, among them remote code execution and SQL injection",
          "No request limit, 429 behaviour or Retry-After guidance is published for the cloud API",
          "Personal API tokens act with their user's full permissions, and OAuth has one scope per API with no read-only form",
          "No official SDK. The client libraries the docs list are community projects the vendor says it does not vet",
          "The MCP server is an Enterprise add-on for the Professional plan and above, which starts at 25 users"
        ],
        "agentNotes": [
          "Send the API token as `Authorization: Bearer \u003ctoken\u003e`, or as the Basic auth password with the user name `apikey`",
          "Read the resource first and send its current `lockVersion` with every PATCH. A stale value returns 409 `UpdateConflict`",
          "POST to the `/form` endpoint of a work package to learn writable fields and allowed values before creating or updating",
          "URL-encode `filters` as a JSON array, and add `pageSize`, `offset` and `select` to keep work package lists small",
          "Run the agent as a dedicated user with a narrow project role, and treat work package text and comments as untrusted input"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.4
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 75,
          "payments": 30,
          "reliability": 52,
          "schema": 76,
          "security": 59,
          "transparency": 79
        },
        "provenanceScore": 95
      },
      "connect": {
        "http": "curl -H \"Authorization: Bearer $API_KEY\" https://community.openproject.org/api/v3/users/42"
      },
      "letme": {
        "capability": "https://letme.dev/tasks.create",
        "tool": "https://letme.dev/openproject"
      },
      "area": "business",
      "unitPrices": [
        {
          "item": "Community (self-hosted)",
          "unit": "seat-month",
          "usd": 0,
          "note": "free, REST API included; not sold as a cloud plan"
        },
        {
          "item": "Basic (cloud)",
          "unit": "seat-month",
          "usd": 7.25,
          "note": "yearly term, from 5 users; $8.50 on a monthly term"
        },
        {
          "item": "Professional (cloud)",
          "unit": "seat-month",
          "usd": 13.5,
          "note": "yearly term, from 25 users; includes the MCP server"
        },
        {
          "item": "Premium (cloud)",
          "unit": "seat-month",
          "usd": 19.5,
          "note": "yearly term, from 100 users"
        }
      ],
      "provenance": {
        "legalEntity": "OpenProject GmbH",
        "domain": "openproject.org",
        "domainRegistered": "2003-10-24",
        "endpointOnVendorDomain": true,
        "terms": "https://www.openproject.org/legal/terms-of-service/",
        "privacy": "https://www.openproject.org/legal/privacy/",
        "statusPage": "https://status.openproject.com",
        "changelog": "https://www.openproject.org/docs/release-notes/",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Terms of Service (last updated 6 August 2026) name OpenProject GmbH, Krausenstrasse 9, 10117 Berlin, Germany, and cover both the cloud and the on-premises Enterprise edition. The German version takes precedence.",
          "The privacy policy (version 30 July 2026) has a section on OpenProject Enterprise Cloud, where OpenProject GmbH is processor and the customer controller. The data processing agreement at https://www.openproject.org/legal/data-processing-agreement/ is part of the terms.",
          "Cloud instances answer at \u003cname\u003e.openproject.com or, on the EU shard, an openproject.eu host. Both are the vendor's domains, apart from the openproject.org site that carries the docs and legal pages. Self-hosted instances answer on the owner's domain.",
          "www.openproject.org/.well-known/security.txt is PGP-signed, names security@openproject.com and expires on 31 December 2026.",
          "RDAP for openproject.org gives a registration date of 2003-10-24 and InterNetX GmbH as registrar."
        ],
        "score": 95
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/openproject.json",
      "live": {
        "slug": "openproject",
        "vendorStatus": {
          "page": "https://status.openproject.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:22.822468534Z"
        },
        "updatedAt": "2026-10-09T07:58:22.822468534Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "monday.com Ltd.",
        "b": "OpenProject GmbH",
        "name": "Vendor"
      },
      {
        "a": "https://api.monday.com/v2",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under monday.com's Terms of Service and Developer Terms. The MCP server, agent toolkit and API SDK on GitHub are MIT",
        "b": "GPL-3.0 for the OpenProject source. Enterprise add-ons need a paid token, and OpenProject Enterprise cloud runs under OpenProject's Terms of Service",
        "name": "Licence"
      },
      {
        "a": "64",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "com.monday/monday.com",
        "b": "not listed",
        "name": "MCP registry"
      },
      {
        "a": "2026-10-07",
        "b": "2026-10-01",
        "name": "Last release"
      },
      {
        "a": "2026-05-05",
        "b": "2026-08-06",
        "name": "Terms last updated"
      },
      {
        "a": "2026-10-01",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "176k npm/wk",
        "b": "16k stars",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "monday.com scores 76.4 (BB) on agent readiness against OpenProject's 57.4 (C), and leads in 6 of 7 scored categories. OpenProject leads on transparency \u0026 trust.",
        "question": "Which is better for AI agents, monday.com or OpenProject?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do monday.com and OpenProject need an API key?"
      },
      {
        "answer": "monday.com has a hosted endpoint at https://api.monday.com/v2. No hosted endpoint is listed for OpenProject.",
        "question": "Can an agent call monday.com and OpenProject without installing anything?"
      },
      {
        "answer": "No open-source release is listed for monday.com. OpenProject is open source (GPL-3.0 for the OpenProject source. Enterprise add-ons need a paid token, and OpenProject Enterprise cloud runs under OpenProject's Terms of Service).",
        "question": "Are monday.com and OpenProject open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 79 against 52",
          "Schema \u0026 documentation, 88 against 76",
          "Agent ergonomics, 82 against 70",
          "Security \u0026 auth, 70 against 59",
          "Payments \u0026 pricing, 50 against 30",
          "Maintenance \u0026 community, 85 against 75"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "A hosted endpoint, with nothing to install",
          "No incidents deducted, where OpenProject loses 5 points for them"
        ],
        "goodFor": "Teams that already run projects on monday.com boards and want an agent to create items, change status, post updates and read board summaries through MCP or GraphQL.",
        "slug": "monday",
        "watchFor": "Personal API tokens have no scopes. Each carries every permission its user has in the app"
      },
      {
        "aheadOn": [
          "Transparency \u0026 trust, 87 against 80"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that want a self-hostable or EU-hosted project tool with Gantt, time tracking and budgets, and an agent working through a documented REST API.",
        "slug": "openproject",
        "watchFor": "83 advisories published against opf/openproject in the twelve months to 8 October 2026, 13 rated critical, among them remote code execution and SQL injection"
      }
    ],
    "job": {
      "capability": "tasks.create",
      "name": "Tasks create"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/asana-vs-monday.json",
        "title": "Asana vs monday.com",
        "url": "https://www.anchorterminal.com/compare/asana-vs-monday"
      },
      {
        "json": "https://www.anchorterminal.com/compare/asana-vs-openproject.json",
        "title": "Asana vs OpenProject",
        "url": "https://www.anchorterminal.com/compare/asana-vs-openproject"
      },
      {
        "json": "https://www.anchorterminal.com/compare/basecamp-vs-monday.json",
        "title": "Basecamp vs monday.com",
        "url": "https://www.anchorterminal.com/compare/basecamp-vs-monday"
      },
      {
        "json": "https://www.anchorterminal.com/compare/basecamp-vs-openproject.json",
        "title": "Basecamp vs OpenProject",
        "url": "https://www.anchorterminal.com/compare/basecamp-vs-openproject"
      },
      {
        "json": "https://www.anchorterminal.com/compare/clickup-vs-monday.json",
        "title": "ClickUp vs monday.com",
        "url": "https://www.anchorterminal.com/compare/clickup-vs-monday"
      },
      {
        "json": "https://www.anchorterminal.com/compare/clickup-vs-openproject.json",
        "title": "ClickUp vs OpenProject",
        "url": "https://www.anchorterminal.com/compare/clickup-vs-openproject"
      },
      {
        "json": "https://www.anchorterminal.com/compare/monday-vs-plane.json",
        "title": "monday.com vs Plane",
        "url": "https://www.anchorterminal.com/compare/monday-vs-plane"
      },
      {
        "json": "https://www.anchorterminal.com/compare/monday-vs-roma.json",
        "title": "monday.com vs Roma",
        "url": "https://www.anchorterminal.com/compare/monday-vs-roma"
      },
      {
        "json": "https://www.anchorterminal.com/compare/monday-vs-shortcut.json",
        "title": "monday.com vs Shortcut",
        "url": "https://www.anchorterminal.com/compare/monday-vs-shortcut"
      },
      {
        "json": "https://www.anchorterminal.com/compare/monday-vs-taiga.json",
        "title": "monday.com vs Taiga",
        "url": "https://www.anchorterminal.com/compare/monday-vs-taiga"
      },
      {
        "json": "https://www.anchorterminal.com/compare/monday-vs-teamwork.json",
        "title": "monday.com vs Teamwork.com",
        "url": "https://www.anchorterminal.com/compare/monday-vs-teamwork"
      },
      {
        "json": "https://www.anchorterminal.com/compare/monday-vs-todoist.json",
        "title": "monday.com vs Todoist",
        "url": "https://www.anchorterminal.com/compare/monday-vs-todoist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/monday-vs-trello.json",
        "title": "monday.com vs Trello",
        "url": "https://www.anchorterminal.com/compare/monday-vs-trello"
      },
      {
        "json": "https://www.anchorterminal.com/compare/monday-vs-wrike.json",
        "title": "monday.com vs Wrike",
        "url": "https://www.anchorterminal.com/compare/monday-vs-wrike"
      },
      {
        "json": "https://www.anchorterminal.com/compare/monday-vs-youtrack.json",
        "title": "monday.com vs YouTrack",
        "url": "https://www.anchorterminal.com/compare/monday-vs-youtrack"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openproject-vs-plane.json",
        "title": "OpenProject vs Plane",
        "url": "https://www.anchorterminal.com/compare/openproject-vs-plane"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openproject-vs-roma.json",
        "title": "OpenProject vs Roma",
        "url": "https://www.anchorterminal.com/compare/openproject-vs-roma"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openproject-vs-shortcut.json",
        "title": "OpenProject vs Shortcut",
        "url": "https://www.anchorterminal.com/compare/openproject-vs-shortcut"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openproject-vs-taiga.json",
        "title": "OpenProject vs Taiga",
        "url": "https://www.anchorterminal.com/compare/openproject-vs-taiga"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openproject-vs-teamwork.json",
        "title": "OpenProject vs Teamwork.com",
        "url": "https://www.anchorterminal.com/compare/openproject-vs-teamwork"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openproject-vs-todoist.json",
        "title": "OpenProject vs Todoist",
        "url": "https://www.anchorterminal.com/compare/openproject-vs-todoist"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openproject-vs-trello.json",
        "title": "OpenProject vs Trello",
        "url": "https://www.anchorterminal.com/compare/openproject-vs-trello"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openproject-vs-wrike.json",
        "title": "OpenProject vs Wrike",
        "url": "https://www.anchorterminal.com/compare/openproject-vs-wrike"
      },
      {
        "json": "https://www.anchorterminal.com/compare/openproject-vs-youtrack.json",
        "title": "OpenProject vs YouTrack",
        "url": "https://www.anchorterminal.com/compare/openproject-vs-youtrack"
      }
    ],
    "scores": [
      {
        "by": 27,
        "edge": "monday",
        "key": "reliability",
        "monday": 79,
        "name": "Reliability",
        "openproject": 52,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 12,
        "edge": "monday",
        "key": "schema",
        "monday": 88,
        "name": "Schema \u0026 documentation",
        "openproject": 76,
        "weight": 13
      },
      {
        "by": 12,
        "edge": "monday",
        "key": "ergonomics",
        "monday": 82,
        "name": "Agent ergonomics",
        "openproject": 70,
        "weight": 13
      },
      {
        "by": 11,
        "edge": "monday",
        "key": "security",
        "monday": 70,
        "name": "Security \u0026 auth",
        "openproject": 59,
        "weight": 14
      },
      {
        "by": 20,
        "edge": "monday",
        "key": "payments",
        "monday": 50,
        "name": "Payments \u0026 pricing",
        "openproject": 30,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 10,
        "edge": "monday",
        "key": "maintenance",
        "monday": 85,
        "name": "Maintenance \u0026 community",
        "openproject": 75,
        "weight": 7
      },
      {
        "by": 7,
        "edge": "openproject",
        "key": "transparency",
        "monday": 80,
        "name": "Transparency \u0026 trust",
        "openproject": 87,
        "weight": 7
      }
    ],
    "summary": "monday.com scores 76.4 (BB) on agent readiness against OpenProject's 57.4 (C), and leads in 6 of 7 scored categories. OpenProject leads on transparency \u0026 trust. Both do tasks create.",
    "verdicts": {
      "monday": "The GraphQL API publishes its full schema, accepts an `Idempotency-Key` header on mutations and reports limits in `RateLimit` headers, and a documented signup API lets an agent create its own account and token. Personal tokens carry every permission their user has, daily calls stop at 1,000 below Pro, and the status page shows two long platform incidents since July 2026.",
      "openproject": "OpenProject's APIv3 has a public OpenAPI 3.1 document with 320 operations, stable error identifiers and optimistic locking, and the same API ships in the free GPL-3.0 Community edition. No request limits are published, API tokens carry their user's full permissions, and 83 security advisories were published in the last twelve months, 13 rated critical."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/monday-vs-openproject",
    "json": "https://www.anchorterminal.com/compare/monday-vs-openproject.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/monday-vs-openproject.md",
    "slim": "https://www.anchorterminal.com/compare/monday-vs-openproject.min.md"
  },
  "markdown": "monday.com scores 76.4 (BB) on agent readiness against OpenProject's 57.4 (C), and leads in 6 of 7 scored categories. OpenProject leads on transparency \u0026 trust. Both do tasks create.\n\n- monday.com: grade BB, 76.4/100, rank #33 of 842. Markdown https://www.anchorterminal.com/tools/monday.md · JSON https://www.anchorterminal.com/api/v1/tools/monday.json\n- OpenProject: grade C, 57.4/100, rank #550 of 842. Markdown https://www.anchorterminal.com/tools/openproject.md · JSON https://www.anchorterminal.com/api/v1/tools/openproject.json\n\n## Which one, for what\n\n### monday.com (BB)\n\nGood for: Teams that already run projects on monday.com boards and want an agent to create items, change status, post updates and read board summaries through MCP or GraphQL.\n\nAhead on:\n- Reliability, 79 against 52\n- Schema \u0026 documentation, 88 against 76\n- Agent ergonomics, 82 against 70\n- Security \u0026 auth, 70 against 59\n- Payments \u0026 pricing, 50 against 30\n- Maintenance \u0026 community, 85 against 75\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- A hosted endpoint, with nothing to install\n- No incidents deducted, where OpenProject loses 5 points for them\n\nWatch for: Personal API tokens have no scopes. Each carries every permission its user has in the app\n\n### OpenProject (C)\n\nGood for: Teams that want a self-hostable or EU-hosted project tool with Gantt, time tracking and budgets, and an agent working through a documented REST API.\n\nAhead on:\n- Transparency \u0026 trust, 87 against 80\n\nAlso in its favour:\n- Open source\n\nWatch for: 83 advisories published against opf/openproject in the twelve months to 8 October 2026, 13 rated critical, among them remote code execution and SQL injection\n\n\n## Score by category\n\n| Category | Weight | monday.com | OpenProject | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 79 | 52 | monday.com +27 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 88 | 76 | monday.com +12 |\n| Agent ergonomics | 13% (16.2 this run) | 82 | 70 | monday.com +12 |\n| Security \u0026 auth | 14% (17.5 this run) | 70 | 59 | monday.com +11 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 50 | 30 | monday.com +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 85 | 75 | monday.com +10 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 80 | 87 | OpenProject +7 |\n| Negative events | ≤15 | 0 | -5 | |\n| **Total** | | **76.4 · BB** | **57.4 · C** | |\n\n## Facts side by side\n\n| Fact | monday.com | OpenProject |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | monday.com Ltd. | OpenProject GmbH |\n| Hosted endpoint | `https://api.monday.com/v2` | no (local only) |\n| Transports | HTTP, Streamable HTTP | HTTP |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under monday.com's Terms of Service and Developer Terms. The MCP server, agent toolkit and API SDK on GitHub are MIT | GPL-3.0 for the OpenProject source. Enterprise add-ons need a paid token, and OpenProject Enterprise cloud runs under OpenProject's Terms of Service |\n| Tools exposed | 64 | none |\n| Read-only variant documented | no | no |\n| llms.txt | yes | no |\n| MCP registry | `com.monday/monday.com` | not listed |\n| Last release | 2026-10-07 | 2026-10-01 |\n| Terms last updated | 2026-05-05 | 2026-08-06 |\n| Privacy policy last updated | 2026-10-01 | no date given |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | yes | not found in the text |\n| Terms or service can change without notice | yes | not found in the text |\n| Arbitration or class-action waiver | yes | not found in the text |\n| Popularity | 176k npm/wk | 16k stars |\n\n## Verdicts\n\n**monday.com.** The GraphQL API publishes its full schema, accepts an `Idempotency-Key` header on mutations and reports limits in `RateLimit` headers, and a documented signup API lets an agent create its own account and token. Personal tokens carry every permission their user has, daily calls stop at 1,000 below Pro, and the status page shows two long platform incidents since July 2026.\n\n**OpenProject.** OpenProject's APIv3 has a public OpenAPI 3.1 document with 320 operations, stable error identifiers and optimistic locking, and the same API ships in the free GPL-3.0 Community edition. No request limits are published, API tokens carry their user's full permissions, and 83 security advisories were published in the last twelve months, 13 rated critical.\n\n## Before you call either\n\n### monday.com\n\n1. Send an `API-Version` header such as 2026-10 on every call. Without it the API uses whichever version is current\n2. Read the board's columns first (`get_board_info` or `boards { columns }`), then write column values as a JSON string keyed by column ID\n3. Reuse one `Idempotency-Key` per mutation when retrying after a timeout or 5xx. After a 429, wait for `Retry-After` or `retry_in_seconds`\n4. Page items with `items_page` and `next_items_page`, at most 500 a page. Cursors expire after 60 minutes\n5. For a narrower grant than a personal token, connect MCP through a custom OAuth app with only scopes such as `boards:read`\n\n### OpenProject\n\n1. Send the API token as `Authorization: Bearer \u003ctoken\u003e`, or as the Basic auth password with the user name `apikey`\n2. Read the resource first and send its current `lockVersion` with every PATCH. A stale value returns 409 `UpdateConflict`\n3. POST to the `/form` endpoint of a work package to learn writable fields and allowed values before creating or updating\n4. URL-encode `filters` as a JSON array, and add `pageSize`, `offset` and `select` to keep work package lists small\n5. Run the agent as a dedicated user with a narrow project role, and treat work package text and comments as untrusted input\n\n## Questions\n\n### Which is better for AI agents, monday.com or OpenProject?\n\nmonday.com scores 76.4 (BB) on agent readiness against OpenProject's 57.4 (C), and leads in 6 of 7 scored categories. OpenProject leads on transparency \u0026 trust.\n\n### Do monday.com and OpenProject need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call monday.com and OpenProject without installing anything?\n\nmonday.com has a hosted endpoint at https://api.monday.com/v2. No hosted endpoint is listed for OpenProject.\n\n### Are monday.com and OpenProject open source?\n\nNo open-source release is listed for monday.com. OpenProject is open source (GPL-3.0 for the OpenProject source. Enterprise add-ons need a paid token, and OpenProject Enterprise cloud runs under OpenProject's Terms of Service).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/monday-vs-openproject.json, and with the fewest tokens: https://www.anchorterminal.com/compare/monday-vs-openproject.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"monday\", \"b\": \"openproject\"}`. From a terminal: `anchor compare monday openproject`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/monday.json and https://www.anchorterminal.com/api/v1/tools/openproject.json\n\n## Other comparisons with monday.com or OpenProject\n\n- [Asana vs monday.com](https://www.anchorterminal.com/compare/asana-vs-monday.md)\n- [Asana vs OpenProject](https://www.anchorterminal.com/compare/asana-vs-openproject.md)\n- [Basecamp vs monday.com](https://www.anchorterminal.com/compare/basecamp-vs-monday.md)\n- [Basecamp vs OpenProject](https://www.anchorterminal.com/compare/basecamp-vs-openproject.md)\n- [ClickUp vs monday.com](https://www.anchorterminal.com/compare/clickup-vs-monday.md)\n- [ClickUp vs OpenProject](https://www.anchorterminal.com/compare/clickup-vs-openproject.md)\n- [monday.com vs Plane](https://www.anchorterminal.com/compare/monday-vs-plane.md)\n- [monday.com vs Roma](https://www.anchorterminal.com/compare/monday-vs-roma.md)\n- [monday.com vs Shortcut](https://www.anchorterminal.com/compare/monday-vs-shortcut.md)\n- [monday.com vs Taiga](https://www.anchorterminal.com/compare/monday-vs-taiga.md)\n- [monday.com vs Teamwork.com](https://www.anchorterminal.com/compare/monday-vs-teamwork.md)\n- [monday.com vs Todoist](https://www.anchorterminal.com/compare/monday-vs-todoist.md)\n- [monday.com vs Trello](https://www.anchorterminal.com/compare/monday-vs-trello.md)\n- [monday.com vs Wrike](https://www.anchorterminal.com/compare/monday-vs-wrike.md)\n- [monday.com vs YouTrack](https://www.anchorterminal.com/compare/monday-vs-youtrack.md)\n- [OpenProject vs Plane](https://www.anchorterminal.com/compare/openproject-vs-plane.md)\n- [OpenProject vs Roma](https://www.anchorterminal.com/compare/openproject-vs-roma.md)\n- [OpenProject vs Shortcut](https://www.anchorterminal.com/compare/openproject-vs-shortcut.md)\n- [OpenProject vs Taiga](https://www.anchorterminal.com/compare/openproject-vs-taiga.md)\n- [OpenProject vs Teamwork.com](https://www.anchorterminal.com/compare/openproject-vs-teamwork.md)\n- [OpenProject vs Todoist](https://www.anchorterminal.com/compare/openproject-vs-todoist.md)\n- [OpenProject vs Trello](https://www.anchorterminal.com/compare/openproject-vs-trello.md)\n- [OpenProject vs Wrike](https://www.anchorterminal.com/compare/openproject-vs-wrike.md)\n- [OpenProject vs YouTrack](https://www.anchorterminal.com/compare/openproject-vs-youtrack.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "monday.com vs OpenProject",
        "url": ""
      }
    ],
    "description": "monday.com scores 76.4 (BB) on agent readiness against OpenProject's 57.4 (C), and leads in 6 of 7 scored categories. OpenProject leads on transparency \u0026 trust. Both do tasks create. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "monday.com BB 76.4",
      "OpenProject C 57.4",
      "scores"
    ],
    "h1": "monday.com vs OpenProject",
    "image": "https://www.anchorterminal.com/assets/og/compare-monday-vs-openproject.png",
    "path": "/compare/monday-vs-openproject",
    "published": "2026-10-01",
    "section": "tools",
    "title": "monday.com vs OpenProject for AI agents, BB 76.4 vs C 57.4",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/monday-vs-openproject"
  },
  "tokens": {
    "markdown": 2550,
    "slim": 780
  },
  "version": 1
}
